CVE-2026-28427Disclosure(nekename / opendeck)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1, the service listening on port 57118 serves static files for installed plugins but does not properly sanitize path components. By including ../ sequences in the request path, an attacker can traverse outside the intended directory and read any file OpenDeck can access. This vulnerability is fixed in 2.8.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-24

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opendeck

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-04); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
opendeck

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-04: 2Mentions · 2026-03-05: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-05: 103-0403-05
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure2
2026-03-051
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-28427 OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1, the service listening on port 57118 serves static files for installed plugins but does not pro… https://www.cve.org/CVERecord?id=CVE-2026-28427

    Post summary

    The statement references CVE-2026-28427 and a CVE record link, indicating a basic disclosure of the vulnerability without additional technical or exploit details.

    01000202
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28427 Path Traversal in OpenDeck Linux Service Enabling Unauthorized File Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28427

    Post summary

    The post announces CVE-2026-28427 as a path traversal flaw that permits unauthorized file access, without detailing PoC, exploit tools, or patch information.

    0000085
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-28427 OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1, the service listening on port 57118 serves static files for installed plugins but does not pro… https://www.cve.org/CVERecord?id=CVE-2026-28427 ----- Traducción: CVE-2026-28427 Ope… http://infoflow.cloud`

    Post summary

    CVE‑2026‑28427 has been disclosed for OpenDeck versions prior to 2.8.1, noting that the service listening on port 57118 serves static files for installed plugins; further details are available via the CVE record link.

    0000058
    56 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnekenameopendeck---

Explore more